CVE-2020-37004 | codexcube Ultimate Project Manager CRM PRO up to 2.0.5 get_article_suggestion Search sql injection (Exploit 48912)
A vulnerability described as critical has been identified in codexcube Ultimate Project Manager CRM PRO up to 2.0.5. This vulnerability affects unknown code of the file /frontend/get_article_suggestion/. Executing a manipulation of the argument Search can lead to sql injection.
This vulnerability is registered as CVE-2020-37004. It is possible to launch the attack remotely. Furthermore, an exploit is available.